# How to parse json in grok

**URL:** <https://discuss.elastic.co/t/how-to-parse-json-in-grok/129465>\
**Category:** Logstash\
**Created:** [April 25, 2018, 11:09am UTC](https://discuss.elastic.co/t/how-to-parse-json-in-grok/129465 "2018-04-25T11:09:11Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 25, 2018, 2:04pm UTC](https://discuss.elastic.co/t/how-to-parse-json-in-grok/129465/2 "2018-04-25T14:04:13Z")

</div>

If the first JSON object never contains a space then the following would work. If it can contain a space I cannot think of a way of doing it except for a complicated ruby filter that takes a string containing the the two JSON objects and counts brackets to split them.

```auto
  dissect { mapping => { "message" => '%{timestamp} %{host} %{appname} %{level} [%{}] [pid:%{}] [%{threadname}] %{ip} - - - %{} [%{}][%{}] %{operation} %{uri} %{}/%{} %{} %{} %{json1} %{json2}' } }
  json { source => "json1" target => "first" }
  json { source => "json2" target => "second" }

```

---

_[View the full topic](https://discuss.elastic.co/t/how-to-parse-json-in-grok/129465)._
